Difference between pages "Hard Drive Passwords" and "BitLocker: how to image"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
m
 
(Traditional Imaging)
 
Line 1: Line 1:
Some hard drives support passwords. These passwords can be implemented in computer's operating system, its BIOS, or even in the hard drive's firmware.  Passwords implemented in the OS are the easiest to remove, those in the firmware are the hardest.
 
  
Sometimes people use the term "password" but the hard drive is really [[Full Disk Encryption|encrypted]], and the password is used to unlock a decryption key. These passwords cannot be removed — the encryption key must be cracked or discovered through another means.
+
= Imaging Options =
  
=Vendors=
+
There are multiple ways to image a computer with bitlocker security in place.
* Disklabs (www.disklabs.com) is able to remove some forms of hard drive passwords.
+
  
* Dell will assist law enforcement in removing the passwords from password-protected hard drives. You need to provide Dell with a copy of the search warrant and the computer's service tag #. Reportedly this can be done over the phone, once you have a good relationship with Dell.
+
== Traditional Imaging ==
  
* [http://www.hdd.profesjonalnie.pl/to.php Seagate HDD Service Device for 2,5" drives BASIC Kit]: The tool works with 2,5" drives of Seagate. Main functionality - ATA PASSWORD removal from 2,5" drives.
+
One can make a traditional image with the image containing encrypted information.
  
* [http://www.acelaboratory.com/pc3000.htm PC-3000 for Windows] has "An opportunity to unlock USER and MASTER passwords used in a HDD".
+
Options to offline decrypt the information, provided the password or recovery password is available, exists some are:
 +
* [http://www.hsc.fr/ressources/outils/dislocker/ dislocker]
 +
* [[EnCase]] (as of version 6) with the (optional) encryption module
 +
* [[libbde]]
  
* [http://www.hdd-tools.com/products/rrs/ With Repair Station you can remove an unknown ATA-password; both security levels are supported: High and Maximum]
+
The recovery password is a long series of digits broken up into 8 segments.
 +
<pre>
 +
123456-123456-123456-123456-123456-123456-13456-123456
 +
</pre>
  
* [http://www.vogon-investigation.com/password-cracker-solution.htm Using the Vogon Password Cracker POD, the protection from the drive can be removed]
+
Note that there is no white space in the recovery password including not at the end, e.g. EnCase does not accept the recovery password if there is trailing white space.
  
* [http://www.salvationdata.com SalvationData] sells a system for "Stage 2 physical data damage" recovery from HDDs. The company sells tools for swapping out platters from one drive into another drive, changing the firmware on drives, and other kinds of operations. You can buy it from http://www.computersciencelabs.com.
+
The recovery password can be recovered from a BitLocker enabled computer provided it can be logged into or if stored in escrow.
 +
 
 +
The basic steps are:
 +
 
 +
# Make a "traditional" full disk image.
 +
# Recover the password, this can be done by booting the original computer, or by creating a clone and booting the clone. (booting from a clone has not been tested at this time.)
 +
## Once booted log into the computer
 +
## Use the BitLocker control panel applet to display the password.  This can also be done from the command-line.
 +
## record the password
 +
#:
 +
# For EnCase v6 or higher with the encryption module installed
 +
## Load the image into EnCase
 +
## You will be prompted for the password.  Simply enter it and continue.
 +
## If you prefer to have an un-encrypted image to work with other tools or share with co-workers, you can "re-acquire" the image from within EnCase. The new image will have unencrypted data.
 +
## After adding the encrypted image into your case, simply right click on the drive in the left panel and select acquire. Select "do not add to case".  You will be presented a dialog window to enter new information about the image.  Make sure the destination you select for your new image does not exist.
 +
 
 +
== Live Imaging ==
 +
 
 +
=== FTK Live Imaging of a physical drive ===
 +
 
 +
Using FTK Imager lite, it was determined a live image of the physical system disk resulted in an image with an encrypted bitlocker container on it.
 +
 
 +
Note that the phrase "physical" here corresponds directly with FTK Imagers use of the term in their image acquire menu.
 +
 
 +
=== FTK Live Imaging of a logical partition ===
 +
 
 +
This has not been verified to work or fail at this time.
 +
 
 +
Note that the phrase "logical" here corresponds directly with FTK Imagers use of the term in their image acquire menu.
 +
 
 +
=== FTK Live Files and Folders collections ===
 +
 
 +
This was not attempted, but it seems reasonable to assume this will collect unencrypted files.
 +
 
 +
== See Also ==
 +
* [[BitLocker Disk Encryption]]
 +
* [[Defeating Whole Disk Encryption]]
 +
 
 +
[[Category:Disk encryption]]
 +
[[Category:Windows]]

Revision as of 02:03, 15 July 2013

Imaging Options

There are multiple ways to image a computer with bitlocker security in place.

Traditional Imaging

One can make a traditional image with the image containing encrypted information.

Options to offline decrypt the information, provided the password or recovery password is available, exists some are:

The recovery password is a long series of digits broken up into 8 segments.

123456-123456-123456-123456-123456-123456-13456-123456

Note that there is no white space in the recovery password including not at the end, e.g. EnCase does not accept the recovery password if there is trailing white space.

The recovery password can be recovered from a BitLocker enabled computer provided it can be logged into or if stored in escrow.

The basic steps are:

  1. Make a "traditional" full disk image.
  2. Recover the password, this can be done by booting the original computer, or by creating a clone and booting the clone. (booting from a clone has not been tested at this time.)
    1. Once booted log into the computer
    2. Use the BitLocker control panel applet to display the password. This can also be done from the command-line.
    3. record the password
  3. For EnCase v6 or higher with the encryption module installed
    1. Load the image into EnCase
    2. You will be prompted for the password. Simply enter it and continue.
    3. If you prefer to have an un-encrypted image to work with other tools or share with co-workers, you can "re-acquire" the image from within EnCase. The new image will have unencrypted data.
    4. After adding the encrypted image into your case, simply right click on the drive in the left panel and select acquire. Select "do not add to case". You will be presented a dialog window to enter new information about the image. Make sure the destination you select for your new image does not exist.

Live Imaging

FTK Live Imaging of a physical drive

Using FTK Imager lite, it was determined a live image of the physical system disk resulted in an image with an encrypted bitlocker container on it.

Note that the phrase "physical" here corresponds directly with FTK Imagers use of the term in their image acquire menu.

FTK Live Imaging of a logical partition

This has not been verified to work or fail at this time.

Note that the phrase "logical" here corresponds directly with FTK Imagers use of the term in their image acquire menu.

FTK Live Files and Folders collections

This was not attempted, but it seems reasonable to assume this will collect unencrypted files.

See Also